Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Transports: stdio vs HTTP
  • State of MCP (stats)
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ’» Developer Tools
  3. Secobserve MCP
S
Health: Not checked yetWe have not completed a health check for this listing yet.No health check has run yet.

Secobserve MCP

User RatingsBe the first to rate and review this MCP server! Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time β€” check back soon.
View Repository

MCP server for SecObserve: triage findings, manage products, import scan reports and SBOMs.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

One-click editor setup isn’t available for this listing yet β€” we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ
No confirmed setup config for this listing yet. We only publish a config block when the install details come from the project itself β€” its README, its docs, or a verified owner. We haven’t found those for secobserve-mcp, and we’d rather show nothing than a guess you’d paste into your client. Follow the project’s own setup instructions for the current steps.
Install Directory Badge Claim listing AlternativesπŸ’» More in Developer Tools

Documentation Overview

secobserve-mcp

MCP server for SecObserve β€” Triage, import and administration from an agent

PyPI Python SecObserve License Glama

Tools β€’ Install β€’ Configure β€’ Register with a client β€’ Design

secobserve-mcp exposes the SecObserve REST API to an LLM agent over the Model Context Protocol: browse and triage observations, manage products, branches and rules, import scan reports and SBOMs, run scans and background jobs, generate VEX documents. Transport is stdio by default. Listed in the official MCP Registry as io.github.nh4ttruong/secobserve-mcp.

Tools

18 tools, not one per endpoint. SecObserve has ~50 REST resources and ~40 named actions; registering a tool for each would cost more context than the data ever returns, so the API is modelled as data and the tools are the interface to it.

ToolPurpose
secobserve_list_resourcesThe catalogue: every resource, its verbs, its actions. Makes no API call, so it is free to call first.
secobserve_describe_resourceExact filters, fields and enums, read from the running instance's OpenAPI schema.
secobserve_list / _getRead, with filters, sorting, pagination and projection.
secobserve_create / _update / _deleteCRUD over any resource in the catalogue.
secobserve_call_actionThe long tail: apply_rules, copy, simulate, license_overview, exports.
secobserve_assess_observationTriage one finding. Writes an observation log, honours the approval workflow.
secobserve_bulk_assess_observationsThe same assessment across up to 250 findings.
secobserve_approve_observation_logApprove or reject pending assessments (four-eyes).
secobserve_product_metricsPre-aggregated counts: current, timeline, the delta between two dates, and how stale they are.
secobserve_upload_fileImport a scan report, SBOM or VEX document from disk.
secobserve_api_importPull findings through a stored API configuration. Blocks; a timeout reports the work as still running and where to watch it land.
secobserve_trigger_scanRun SecObserve's built-in OSV or VulnerableCode scan. Same blocking behaviour.
secobserve_run_periodic_taskTrigger a background job, or list the registered ones.
secobserve_statusVersion, health, public settings, queue statistics, PURL types.
secobserve_vex_documentGenerate or revise a CSAF / OpenVEX / CycloneDX document.

Prompts

Six prompts, for the work that is a sequence of calls rather than one. A prompt is fetched by name when someone picks it, so it costs nothing per session β€” unlike a tool schema, which is sent on every connection.

PromptPurpose
triage-productWork one product's open findings, highest severity and fix_available first, assessing each with evidence.
daily-changesWhat changed since local midnight: new, parser-changed, resolved, human-assessed.
weekly-changesThe same feed over the past 7 days, broken down by day.
daily-reportToday's counts per product, what moved today, what is still open.
weekly-reportThe same three parts over the past 7 days, for the report someone sends on.
monthly-reportA month's closing numbers and the month-over-month delta.

Each one carries the caveats that decide whether the report is right: metrics cover the default branch only and answer 200 with every count at zero when the job has not run, no filter expresses a calendar month, and nothing in SecObserve is a due date or an SLA.

Install

bash
uvx secobserve-mcp --help

uvx downloads and runs it without installing anything permanently. In VS Code: one-click install.

To put it on your PATH instead:

bash
uv tool install secobserve-mcp

Once you have done that, uv tool owns the name: a bare uvx secobserve-mcp runs that pinned copy forever and never notices a newer release, so keep it current with uv tool upgrade secobserve-mcp. The client configurations below therefore say uvx secobserve-mcp@latest, which revalidates against PyPI on each launch β€” once per client session, not once per command. --check deliberately stays on the bare name, because its job is to report on the copy your clients are actually running.

From a checkout, for development:

bash
uv venv && uv pip install -e ".[dev]"

Configure

VariableDefaultNotes
SECOBSERVE_BASE_URLhttp://localhost:8000Base URL without /api.
SECOBSERVE_API_TOKENβ€”User or product API token. Recommended.
SECOBSERVE_JWTβ€”Alternative to an API token.
SECOBSERVE_TIMEOUT60Seconds. SecObserve imports and scans inside the request, and a timeout does not cancel one; raise it to get the counts back from the call itself.
SECOBSERVE_VERIFY_SSLtrueSet false only for a self-signed dev certificate.
SECOBSERVE_READ_ONLYfalsetrue refuses every non-GET call.
SECOBSERVE_ALLOW_DELETEfalsesecobserve_delete is off until this is set.
SECOBSERVE_IMPORT_DIRworking directoryUploads may only be read from this tree.
SECOBSERVE_EXPORT_DIR./secobserve-exportsExports and VEX documents are written here.
SECOBSERVE_AUDIT_LOGtrueOne JSON line per tool call on stderr. false switches it off.

Create a user API token:

Terminal
curl -X POST "$SECOBSERVE_BASE_URL/api/authentication/create_user_api_token/" \
  -H "Content-Type: application/json" \
  -d '{"username": "you", "password": "...", "name": "mcp"}'

Check the wiring before handing it to a client:

bash
uvx secobserve-mcp --check

It prints the instance version, the authenticated user, whether read-only and delete are enabled, and how this install compares to the newest release on PyPI. That last part is the only place this server calls pypi.org, it needs one short-lived request, and it degrades to a single line when the index is unreachable.

Run as a container

Terminal
docker run --rm -p 8931:8931 \
  -e SECOBSERVE_BASE_URL=https://secobserve.example.com \
  -e SECOBSERVE_API_TOKEN=... \
  ghcr.io/nh4ttruong/secobserve-mcp \
  --transport http --host 0.0.0.0 --shared-identity

The image is built for linux/amd64 and linux/arm64, runs as a non-root user, and answers GET /healthz with its version. /healthz is liveness only and never calls SecObserve, so a backend outage does not get this server restarted.

--shared-identity is required and not in the image's default command: the token is baked into the environment, so every caller of the port acts as that one SecObserve identity, and the server refuses to start over HTTP until someone says that is intended. It then refuses every write, because an assessment made under a shared token records the wrong actor in the observation log and in four-eyes approval. Arguments to docker run replace CMD rather than extend it, which is why the transport flags are repeated above.

Keep it behind a gateway that authenticates the caller, and off any public port. For a single user, uvx over stdio is the better fit: one process, one token, writes included.

Register with a client

The server prints its own registration snippet, so none of the blocks below have to be copied by hand:

bash
uvx secobserve-mcp --print-config claude   # or: codex, vscode, json

It reads SECOBSERVE_BASE_URL from the environment and always leaves the token as a placeholder β€” the snippet is meant to be pasted somewhere, and a token should not travel with it. The hint goes to stderr, so --print-config json > mcp.json writes a clean file.

Claude Code

Terminal
claude mcp add secobserve --env SECOBSERVE_BASE_URL=http://localhost:8000 --env SECOBSERVE_API_TOKEN=... -- uvx secobserve-mcp@latest

Codex CLI

In ~/.codex/config.toml:

toml
[mcp_servers.secobserve]
command = "uvx"
args = ["secobserve-mcp@latest"]
env = { SECOBSERVE_BASE_URL = "http://localhost:8000", SECOBSERVE_API_TOKEN = "..." }

Other MCP clients

Most clients take the same JSON shape:

config.json
{
  "mcpServers": {
    "secobserve": {
      "command": "uvx",
      "args": ["secobserve-mcp@latest"],
      "env": {
        "SECOBSERVE_BASE_URL": "http://localhost:8000",
        "SECOBSERVE_API_TOKEN": "..."
      }
    }
  }
}

For a shared deployment, run streamable HTTP with stateless JSON behind a gateway that authenticates the caller:

bash
uvx secobserve-mcp --transport http --host 127.0.0.1 --port 8931 --shared-identity

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Developer Tools View all alternatives
  • Openapi MCP Server logoOpenapi MCP Server

    Connect any HTTP/REST API server using an Open API spec (v3)

    πŸ’» Developer Tools3 views
    Compare vs Openapi MCP Server β†’
  • Claude Task Master logoClaude Task Master

    AI-powered task management system for AI-driven development. Features PRD parsing, task expansion, multi-provider support (Claude, OpenAI, Gemini, Perplexity, xAI), and selective tool loading for optimized context usage.

    πŸ’» Developer Tools8 views
    Compare vs Claude Task Master β†’
  • MCP Server Docker logoMCP Server Docker

    Integrate with Docker to manage containers, images, volumes, and networks.

    πŸ’» Developer Tools3 views
    Compare vs MCP Server Docker β†’
  • Docker MCP logoDocker MCP

    Docker container management and operations through MCP

    πŸ’» Developer Tools3 views
    Compare vs Docker MCP β†’

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about Secobserve MCP

We don't have a confirmed install command for secobserve-mcp yet, so we don't publish a generated one β€” a guessed package name would point at the wrong package or none at all. Follow the project's own README or setup instructions (https://github.com/nh4ttruong/secobserve-mcp) for the current steps.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewSecobserve MCP AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/secobserve-mcp?style=directory)](https://allmcps.com/mcp/secobserve-mcp)
HTML Embed
<a href="https://allmcps.com/mcp/secobserve-mcp"><img src="https://allmcps.com/api/badge/secobserve-mcp?style=directory" alt="Secobserve MCP on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ’»Developer Tools
More technical detailsExpand β–Ύ
Last updatedSep 28, 2026
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
27Quality signal: Emerging Β· 27/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership8/20
Documentation & tools11/30
Adoption & activity1/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… FeaturedAllMCPs Server logo

AllMCPs Server

The official MCP server for AllMCPs.com - submit and manage tools directly from your AI. The open directory for MCP servers. Connect Claude, Cursor, Windsurf, and AI agents to databases, tools, files, and APIs. Explore 10,000+ servers. AllMCPs is the premier, open directory for discovering, evaluating, and installing Model Context Protocol (MCP) servers to equip AI agents and LLMs with real-world superpowers.

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge and attach your website β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ’» Developer Tools β†’Best MCP servers for Developers β†’Alternatives to Secobserve MCP β†’Install in Claude DesktopInstall in CursorInstall in VS CodeSetup guides for all 13 MCP clients